On the crypto side, the values are encrypted client-side before they’re sent. This means the service stores ciphertext it has no ability to decrypt. So the worst case for a backend compromise is someone getting encrypted blobs plus some metadata.
On the controls side, SAST scanning in CI, and minimizing deps as much as possible in the client and the service.
Comments
Looks pretty cool, what steps are you taking to ensure that the backend is secure?
On the crypto side, the values are encrypted client-side before they’re sent. This means the service stores ciphertext it has no ability to decrypt. So the worst case for a backend compromise is someone getting encrypted blobs plus some metadata.
On the controls side, SAST scanning in CI, and minimizing deps as much as possible in the client and the service.